Introduction
Exit readiness converts a privately held company from an operating story into an evidence-backed proposition that can withstand buyer, lender, auditor, tax, legal, regulatory and investment-committee scrutiny. The work is difficult because evidence sits across accounting systems, bank records, customer contracts, payroll, tax filings, ownership registers, board records, data-protection files and the knowledge of a small number of people. A buyer's advisers test whether those materials agree. An unresolved difference can delay diligence, change price, widen warranties, increase escrow or end a process.
The Topic Tracker asks whether agentic workflows can build the data room, reconcile the financials, identify nominee-structure landmines and draft the vendor due-diligence report before buyer advisers find the gaps. This paper develops a controlled answer for B4 GCC SME and family-business owners and A1 international institutional allocators. An agentic system may collect, classify, compare, calculate, draft and route evidence. It has no authority to certify accounts, determine legal ownership, give a tax opinion, waive a disclosure, approve a valuation, answer on behalf of management or bind a transaction.
The UAE context requires particular care. Cabinet Decision No. 109 of 2023 uses a 25 per cent ownership or voting-right test, extends the analysis through any number of legal persons, considers the right to appoint or dismiss a majority of directors and provides a senior-management fallback when no natural person can be identified [1,2]. Its nominee-board-member provisions require specified notifications within 15 days [1]. Federal Decree-Law No. 37 of 2022 supplies a governance framework for family companies and intergenerational transfer [6]. The Ministry of Economy and Tourism's current financial-crimes legislation page provides the official legislative register used for this review [52]. These rules make an ownership chart an evidence object rather than a decorative slide.
Agentic technology also needs a bounded definition. Anthropic's tool-use documentation describes a model that emits a tool request and an application that executes it [34-36]. The Model Context Protocol, or MCP, provides a standard interface for tools and data, with explicit authorisation and security requirements [41-44]. These capabilities can support a controlled diligence workflow. They do not establish the reliability of a particular answer, the completeness of a data room or a measured reduction in transaction time.
The paper answers six questions:
- What must be true before a seller is ready for vendor due diligence?
- How should a machine-readable data room preserve provenance, permissions and privilege?
- Which reconciliations and red-flag tests can be automated safely?
- Where must finance, legal, tax, cyber, HR and management reviewers retain decision rights?
- How should agent outputs be evaluated before use in a transaction process?
- How can a twelve-month readiness programme be converted into evidence gates without claiming unobserved acceleration?
The analysis reviews 52 official, primary, standards-body and vendor-authored sources available through 2 August 2026. It proposes a canonical evidence object, a data-room taxonomy, a reconciliation ledger, a red-flag record, a controlled report-drafting pipeline and an acceptance record. [Unverified illustrative scenarios] supply worked operating examples only. Attributed Matchpoint or client revenue, cash cost reduction, loss reduction and alpha remain USD 0 until approved observed evidence exists.
| Research proposition | Evidence position | Operating treatment |
|---|---|---|
| Agents can call tools and work through multi-step tasks | Documented capability [34-36] | Permit only approved tools, scopes and environments |
| MCP can connect agents to data and services | Documented protocol capability [41-44] | Enforce audience-bound tokens, least privilege and no token passthrough |
| A data room can be built faster with agents | No observed T37 benchmark supplied | Treat as a testable target |
| Twelve months can be compressed | No observed T37 benchmark supplied | Use a gated readiness sequence; record actual elapsed time |
| An agent can sign a VDD conclusion | No authority established | Prohibit; named professionals retain sign-off |
B4 And A1 Decision Perimeter
B4 seller objective
The Topic Tracker defines B4 as GCC SME and family-business owners, managing directors and next-generation leaders, commonly within an AED 10 million to AED 250 million revenue range. Their exit-readiness objective is to present an intelligible business, preserve negotiating credibility, reduce avoidable surprises and retain management capacity during a transaction. The owner may also need to resolve family governance, intercompany balances, shareholder loans, related-party arrangements, informal permissions and nominee structures before a buyer can assess control.
Exit readiness is a management programme. It joins strategic perimeter, ownership, accounts, taxation, operations, customers, people, technology, intellectual property, licences, litigation, environmental matters and data protection. A data room created without a disclosure strategy can expose inconsistent or unnecessary material. A report drafted without verified source links can convert an unresolved issue into a misleading assertion.
A1 investor objective
The Topic Tracker defines A1 as international institutional allocators, including pensions, insurers, endowments and funds of funds evaluating UAE and GCC private markets. An A1 reader is interested in the reliability of the evidence chain and the governance surrounding it. The relevant question is whether a transaction team can move from a seller assertion to the underlying record, determine who reviewed the conclusion and identify exceptions that remain open.
Institutional users also need comparability. A private-company data room may use local accounting, tax, ownership and employment records. An investment committee may evaluate the opportunity through a different reporting, valuation, sanctions, privacy and risk-management lens. The VDD package should preserve local legal meaning while exposing a clear mapping to the buyer's diligence questions. IFRS 3, IFRS reporting materials and IVS data, model and documentation principles provide useful financial-reporting and valuation context [25-28,51]. OECD corporate-governance principles add a transparency and shareholder-rights frame [50]. They do not replace transaction-specific accounting or valuation advice.
Decision rights
| Role | Permitted work | Retained authority |
|---|---|---|
| Seller management | Supply explanations, approve perimeter and confirm management representations | Truth and completeness of seller representations |
| Finance team | Reconcile ledgers, management accounts, statutory accounts, tax and bank evidence | Accounting judgements within approved authority |
| External accountant or VDD provider | Perform agreed work and report findings | Professional conclusion within engagement terms |
| Legal counsel | Review ownership, contracts, licences, disputes, disclosure and privilege | Legal interpretation and transaction advice |
| Tax adviser | Review filings, positions, transfer pricing and restructuring | Tax opinion within engagement terms |
| Agentic workflow | Ingest, classify, compare, calculate, draft, route and log | None over professional or transaction decisions |
| Buyer and advisers | Conduct independent diligence and negotiate protections | Buy-side decision and reliance |
Companion-topic boundary
The Topic Tracker describes T37 as an AI companion to P116 and the broader M&A cluster. P116 is titled Build, Buy or Partner: The UAE Market-Entry Decision. The linkage is indirect: P116 concerns entry route, while T37 concerns seller readiness and vendor diligence. T37 therefore treats P116 as a potential buyer-context input and does not claim that P116 is an exit-readiness paper or a published companion page.
Vendor Due Diligence And Exit Readiness
Purpose
Vendor due diligence is an independent or adviser-led investigation commissioned by the seller and made available, subject to agreed terms, to potential buyers. Its scope varies. Financial VDD may analyse quality of earnings, revenue, margins, cash conversion, working capital, net debt, forecasts and accounting policies. Tax VDD may consider filings, corporate tax, VAT, transfer pricing, customs, payroll and transaction structure. Legal, commercial, operational, technology, cyber, HR, ESG and other workstreams may sit beside it.
The paper uses VDD as a controlled information-production process. It does not imply assurance. IAASB's revised ISRS 4400 distinguishes agreed-upon procedures from assurance and requires factual findings to be reported according to the agreed procedures [24]. PCAOB AS 1105 and AS 1215 provide a useful evidence and documentation logic: relevance, reliability, source, controls, contradictory material and a record sufficient to understand the work performed [21,22]. The applicable professional standard depends on the engagement, jurisdiction and practitioner.
Readiness before launch
A seller is operationally ready when the proposed perimeter is defined, core evidence has been assembled, material balances reconcile, important exceptions have owners and dates, data-sharing controls are in place and the report can distinguish fact, management explanation, adviser analysis and unresolved matter. Readiness does not require a perfect company. It requires an accurate evidence position and a controlled plan for open items.
| Readiness gate | Minimum acceptance evidence | Stop condition |
|---|---|---|
| Perimeter | Entity, branch, business, geography and period map | Deal perimeter remains disputed |
| Ownership | Legal and beneficial ownership chain with source records | Natural-person control cannot be supported |
| Financials | Trial balance to statements and management reporting bridge | Unexplained material differences |
| Cash | Bank accounts, statements and reconciliation | Missing account or unsupported restriction |
| Revenue | Contract, invoice, ledger and cash evidence sample | Material population cannot be reproduced |
| Tax | Registration, returns, payments and open positions | Known filing gap lacks owner and response |
| Data | Processing, sharing, access and retention controls | Sensitive data shared without authority |
| Report | Every consequential statement linked to evidence or labelled | Draft presents unsupported assertion as fact |
Information asymmetry
The seller knows the operating history and may lack a transaction-ready record. The buyer lacks that history and tests the business under a different risk lens. The diligence design should reduce information asymmetry through traceability. The system should never manufacture certainty. A missing contract remains missing. A management explanation remains a management explanation until corroborated. A reported trend remains dependent on population completeness, accounting policy and period consistency.
Controlled Agentic Architecture
Components
The proposed architecture has seven layers: source systems; read-only acquisition; evidence registry; deterministic reconciliation; bounded agent tools; human review; and authorised publication. The source system remains authoritative. The evidence registry records a cryptographic hash, source, acquisition time, owner, classification, permission, transaction period and supersession state. Deterministic code performs totals, joins, currency conversions and tie-outs. Agents organise, analyse and draft using those controlled objects.
Anthropic documents an agentic loop in which the model requests a tool and the application returns the result [34,35]. Claude's managed-agent documentation also exposes permission policies and MCP connections [36]. These are platform capabilities. A production VDD environment must add transaction-specific identity, authorisation, segregation, logging, retention, legal-hold, review and export controls.
Tool contract
Each tool needs a narrow contract. A list-documents tool may return identifiers and classifications. A read-document tool may permit selected folders and deny privileged or restricted material. A reconcile-trial-balance tool may accept a versioned trial-balance identifier and mapping table, then return exact differences. A draft-finding tool may create a proposed finding with citations, while a separate human-controlled action accepts it into a report.
MCP authorisation guidance requires audience-bound tokens and rejects token passthrough [41]. MCP security guidance addresses confused-deputy and access risks [42]. Client best practices call for clear server identity and user control [43]. Tool annotations can communicate read-only, destructive, idempotent and open-world characteristics [44]. The protocol's authorisation tutorial adds practical implementation context [45]. These principles support a rule that a diligence agent receives the minimum capability needed for the current task.
Segregation
| Zone | Content | Agent access |
|---|---|---|
| Source vault | Original exports and signed documents | Read through approved acquisition service |
| Working evidence | Normalised copies, indexes and OCR output | Read; create derived objects |
| Privileged legal | Legal advice and privileged analyses | Denied unless counsel creates an approved enclave |
| Personal data | Employee, customer and counterparty personal data | Field-limited, purpose-bound access |
| Draft report | Findings, reconciliations and management responses | Create proposals; no final approval |
| Published room | Approved disclosure set | Read-only after release manifest is signed |
NIST zero-trust guidance focuses access decisions on users, assets and resources, with no implicit trust based on network location [47,48]. NCSC secure-AI guidance organises controls across design, development, deployment and operation and identifies prompt injection, data poisoning and supply-chain risks [32,33]. These principles are directly relevant to a VDD environment containing valuable and confidential records.
No autonomous disclosure
An agent should never add a document to a buyer-facing room, send a diligence answer, change a financial source record, alter an ownership register or approve a report. A release requires an approved manifest containing the document identifier, version, hash, classification, legal review state, business owner and disclosure audience. The published room should be reproducible from that manifest.
Canonical Evidence Object
Minimum schema
Every input used in a finding should be represented by an evidence object. The object can point to a whole document, a table, a row, a contract clause or an external register result. It separates what the source says from how an analyst interprets it.
| Field | Purpose |
|---|---|
| Evidence ID | Stable internal reference |
| Source URI | Location in the controlled repository or external authority |
| Source system | Ledger, bank, contract store, tax portal or register |
| Hash | Detects file or payload change |
| Acquired at/by | Establishes custody and tool identity |
| Entity and period | Connects evidence to transaction perimeter |
| Classification | Public, internal, confidential, personal, privileged or restricted |
| Extract | Exact machine-readable field or bounded excerpt |
| Transformation | OCR, mapping, currency, filter or calculation applied |
| Reviewer state | Unreviewed, checked, accepted, rejected or superseded |
| Citation | Report-ready pointer back to evidence |
PCAOB guidance notes that the reliability of information produced by a company depends on the controls over accuracy and completeness, and that electronic information may need additional evaluation [21,23]. This logic supports population-level controls before an agent analyses a spreadsheet export. A hash establishes identity of the bytes acquired. It does not establish truth, completeness or correct accounting treatment.
Evidence hierarchy
Executed documents, regulator or registry records, bank-issued statements, filed returns and approved statutory accounts usually carry stronger source authority than unsigned drafts, spreadsheets, emails or management recollection. Context matters. An executed contract may have been amended. A bank statement may exclude a different account. A registry may be stale. The hierarchy should guide review and never silently resolve a contradiction.
Contradictions and supersession
When two sources disagree, the system creates a contradiction record. It identifies both evidence objects, the affected assertion, materiality, owner, proposed resolution and current state. Deleting or overwriting the weaker record destroys useful diligence history. Supersession links preserve the prior version and the reason the new record controls.
Electronic records
UAE Federal Decree-Law No. 46 of 2021 provides that an electronic document does not lose legal force merely because it is electronic and addresses storage, signatures, seals and trust services [8]. The law supports electronic transaction infrastructure. Transaction counsel should determine the evidential treatment of a particular signature, document or jurisdictional requirement. The VDD registry should retain signature status, certificate information and validation evidence where relevant.
Data-Room Taxonomy And Build Automation
Taxonomy
A useful taxonomy follows buyer questions while preserving the seller's source structure. The top level can cover corporate and ownership; finance; tax; commercial; customers; suppliers; operations; property and assets; people; pensions and benefits; technology and cyber; intellectual property; privacy; regulatory and licences; disputes; insurance; ESG; and transaction-specific material.
Every folder should have a scope statement, owner, disclosure class and acceptance checklist. An empty folder should mean one of three declared states: no relevant material; material requested and outstanding; or access restricted. An empty folder should never be interpreted automatically as “not applicable”.
Automated acquisition
Acquisition jobs should be deterministic and idempotent. They capture source metadata, retain the original bytes, calculate a hash, scan for malware, classify content and create a proposed index entry. OCR output and table extraction remain derived artefacts. The original remains available for review. Scanned, password-protected, corrupted or low-confidence documents are routed for manual handling.
Classification and duplicate control
Exact hashing detects byte-for-byte duplicates. Near-duplicate detection can identify renamed copies, scanned versions or documents with changed headers. An agent may propose that two items are duplicates. A reviewer determines whether they are legally or commercially equivalent. A signed agreement and an unsigned working copy can contain identical text and have different evidential status.
Completeness manifests
Each workstream maintains an expected-population manifest. For bank accounts, the population may start with the chart of accounts, treasury list, bank confirmations and tax-return disclosures. For customer contracts, it may start with the revenue ledger and contract-management system. Completeness means that these independent populations have been reconciled or that differences are explicitly recorded.
| Build test | Automated result | Human acceptance |
|---|---|---|
| File integrity | Hash, size, type and malware status | Source identity appears credible |
| Classification | Proposed sensitivity and workstream | Privacy, privilege and disclosure are correct |
| Extraction | Text, tables, dates and parties | Material fields agree to original |
| Duplicate | Exact and near-match candidates | Legal and commercial equivalence determined |
| Completeness | Expected-versus-present exceptions | Population and exceptions approved |
| Release | Signed manifest and hashes | Counsel and business owner approve disclosure |
Privacy by design
The UAE data-protection framework addresses consent or other processing conditions, data-subject rights and cross-border transfer requirements [9]. ICO M&A guidance advises organisations to establish what personal data is transferred, why it was collected, the lawful basis, documentation, security and transparency [19]. EU data-protection principles include purpose limitation, minimisation, storage limitation, accuracy, confidentiality and accountability [20]. The diligence room should therefore use field-level redaction, controlled access, time limits and recorded purpose rather than broad copying.
Financial Reconciliation Engine
Reconciliation graph
The core finance control is a graph, not a single spreadsheet. It links general ledger and trial balance to statutory accounts, management accounts, tax returns, bank accounts, revenue subledgers, receivables, payables, payroll, inventory and forecast inputs. Each bridge records mapping, period, currency, accounting policy, manual adjustment, source, owner and reviewer.
A deterministic calculation should perform the tie-out. An agent can explain differences and assemble supporting evidence. Numerical answers should be produced by validated code with declared precision and rounding. Free-form model calculation creates avoidable risk.
Trial balance to reported results
The system first proves that the trial balance is complete for each entity and period. It then maps account codes to financial-statement and management-reporting lines. Consolidation entries, eliminations, foreign-exchange differences, late journals, prior-period adjustments and reclassifications receive separate evidence objects. A bridge that nets unrelated items can hide the cause of a difference.
Revenue and cash
Revenue analysis should connect contract, order, fulfilment, invoice, ledger, receivable and cash. The available path differs by business model. Population completeness, cut-off, credit notes, rebates, returns, related parties and unusual manual journals matter. IAS 2 is relevant to inventory measurement and cost recognition where the target holds inventory [26]. The applicable reporting framework and policy require professional review.
Quality of earnings
Quality-of-earnings adjustments should be represented as proposed records rather than edits to source EBITDA. Each record stores the reported amount, proposed adjustment, category, period, recurring assessment, cash effect, tax effect, evidence, management view, adviser view and review status. Run-rate, synergy and forecast adjustments need especially clear labelling because they extend beyond recorded history.
Working capital and net debt
Working-capital analysis should preserve account-level definitions, seasonality, deal perimeter, cut-off and normalisation method. Net-debt analysis should separately identify cash, borrowings, accrued interest, leases, shareholder balances, deferred consideration, guarantees, restricted cash and debt-like or cash-like proposals. Classification is a negotiation and advice question. The agent can produce the evidence schedule and proposed mapping.
Tax, Related Parties And Restructuring
Corporate tax records
The UAE Ministry of Finance provides the federal corporate-tax framework, and the Federal Tax Authority publishes corporate-tax guidance and FAQs [10,11]. A tax data room should connect registration, tax period, return, financial statements, elections, calculations, payment, correspondence and open matters. A filing receipt proves submission. It does not prove that the tax position is correct.
Transfer pricing and related parties
The FTA transfer-pricing guide addresses the arm's-length principle and documentation [11]. The VDD engine should reconcile related parties across the ledger, ownership records, director declarations, contracts, tax documentation and management confirmations. It should flag transactions without agreements, pricing support, settlement evidence or a consistent counterparty identity. The tax adviser determines the position and remediation.
Pre-sale restructuring
Reorganisations can alter ownership, tax basis, licences, contracts and employee relationships. UAE Ministry of Finance decisions address intra-group transfers, taxable income and restructuring relief [12]. A proposed pre-sale transfer should therefore be represented as a dependency graph with legal steps, tax conditions, accounting entries, approvals and completion evidence. An agent may monitor conditions. It should not conclude that relief applies.
Tax red flags
| Signal | Required follow-up | Decision owner |
|---|---|---|
| Return and ledger differ | Reconcile period, entity, basis and adjustments | Tax and finance advisers |
| Related party absent from register | Confirm ownership, control and counterparty | Legal, tax and management |
| Material manual tax journal | Retrieve calculation and approval | Finance and tax |
| Restructuring step incomplete | Establish legal and tax completion evidence | Legal and tax |
| Filing or payment gap | Confirm obligation, exposure and remediation | Tax adviser |
Ownership, Nominees And Family Governance
Beneficial ownership
Cabinet Decision No. 109 of 2023 requires a natural-person analysis based on ownership, voting rights or control, with a 25 per cent threshold and tracing through any number of legal persons [1]. It also considers the right to appoint or dismiss a majority of directors and uses a senior-management fallback where the beneficial owner cannot be identified [1,2]. FATF Recommendation 24 and its guidance call for adequate, accurate and up-to-date beneficial-ownership information [3,4].
The VDD ownership graph should model legal owners, beneficial owners, intermediate entities, trusts or foundations where relevant, voting arrangements, options, pledges, board-appointment rights, nominee roles and changes over time. Each edge needs a source document and effective date. A percentage-only chart can miss control.
Nominee-board-member checks
The UAE decision defines and regulates nominee board members and sets notification periods [1]. FATF's glossary distinguishes nominees from beneficial owners and focuses on the nominator's instructions [5]. The agentic workflow should compare corporate registers, board minutes, powers of attorney, service agreements, correspondence and declarations for indications that formal title and actual instruction differ. Every such signal requires counsel and management review.
Family-company governance
Federal Decree-Law No. 37 of 2022 seeks to regulate family-company ownership and governance, facilitate generational transfer and support continuity [6]. Exit readiness should capture the memorandum, shareholder agreements, family charter where applicable, transfer restrictions, pre-emption, valuation mechanisms, dispute provisions, succession arrangements and approvals. The proposed transaction may require family and corporate decisions on different tracks.
Sanctions and anti-corruption
DOJ's compliance-program evaluation asks how a company conducts M&A due diligence, integrates acquired entities and manages emerging-technology risks including AI [13]. The DOJ and SEC FCPA guide addresses successor liability and M&A compliance [14]. OFAC's compliance framework calls for sanctions risk assessment and integration of compliance into M&A [15]. OFSI guidance places weight on reasonable, documented ownership-and-control diligence [16]. OECD materials support comprehensive risk-based diligence in corporate transactions [17,18].
These sources are jurisdiction-specific and fact-dependent. They support a control category, not a legal conclusion for every transaction. The seller should record screening source, search parameters, date, ownership analysis, reviewer, false-positive resolution and escalation.
Commercial, Operational And Contract Analysis
Customer and supplier populations
Commercial diligence begins with reproducible populations. Customer and supplier masters should be reconciled to revenue, receivables, purchases, payables, contracts and bank evidence. Names need a controlled entity-resolution table. The system should retain the original legal name, trading name, group relationship, country, identifier and confidence of every proposed match.
Contract extraction
An agent can propose extraction of party, term, renewal, termination, change-of-control, assignment, exclusivity, price, indexation, volume, service level, liability, governing law and notice provisions. Counsel reviews material clauses and the effect of amendments. Extraction confidence should be field-specific. A high average confidence can conceal one decisive low-confidence clause.
Concentration and churn
Deterministic code should calculate revenue concentration, retention, churn, price-volume-mix and cohort metrics from approved populations. Management explanations, lost-customer reasons and pipeline classification remain separate qualitative evidence. The report should state the denominator, currency, period, entity set and treatment of acquisitions or discontinued operations.
Operating claims
Operational claims such as capacity, utilisation, on-time delivery, defect rate, backlog, recurring revenue or active customer count require definitions and source controls. An agent can compare claims across board packs, sales materials and source systems, then create contradiction records. It should not select the most favourable number.
| Claim | Evidence chain | Common exception |
|---|---|---|
| Contracted backlog | Executed contract to fulfilment schedule | Non-binding order or termination right |
| Recurring revenue | Contract terms to invoice and renewal history | One-off service classified as recurring |
| Customer retention | Approved cohort and denominator | Exclusion or acquisition changes population |
| Gross margin | Revenue and cost mapping | Unallocated labour, freight or rebates |
| Capacity | Asset register and operating record | Theoretical capacity presented as available |
Forecast bridge
The forecast should bridge historical run rate to price, volume, customer, product, capacity, hiring, capex and working-capital assumptions. Each assumption stores owner, source, approval and sensitivity. The agent can identify whether a forecast depends on unsigned contracts, unavailable capacity or unresolved financing. The board and advisers retain forecast ownership.
Legal, Hr, Ip, Privacy And Cyber Workstreams
Legal records
Legal readiness includes formation, constitutional documents, ownership, board and shareholder approvals, licences, material contracts, financing, guarantees, assets, property, disputes, insurance and regulatory correspondence. The Commercial Companies Law and later amendments provide the UAE corporate-law backdrop [7]. Free-zone, financial-free-zone and emirate-specific rules may also apply. Counsel should define the governing regime for each entity.
The agent can index documents, extract dates and parties, compare registers, identify missing signatures and route anomalies. It should never decide privilege, materiality, enforceability, disclosure sufficiency or legal exposure. Privileged documents remain outside the ordinary model context unless counsel expressly creates a controlled workflow.
People and employment
The HR workstream should reconcile employee master data, payroll, benefits, visas, contracts, incentive arrangements, accrued leave, terminations and disputes. Personal data should be minimised before model access. Named employee data may be unnecessary for many aggregate analyses. Redacted or pseudonymised evidence can support population tests while preserving a separate key under restricted control.
Intellectual property
The evidence chain for intellectual property connects creation, assignment, registration, licence, source-code or content repository, contractor terms and revenue dependence. An agent can identify individuals or suppliers associated with material development and compare them with assignment records. Counsel determines ownership and remediation.
Privacy and cyber
The privacy workstream should identify personal-data categories, purposes, systems, processors, sharing, retention, incidents and cross-border flows. The cyber workstream should map critical assets, identities, logging, backups, vulnerability management, incidents, third parties and recovery tests. NIST's Cybersecurity Framework 2.0 and zero-trust publications provide governance and access-control structures [46-48]. NCSC's AI guidance adds controls for model, data and supply-chain risks [32,33].
AI use in the target
DOJ's September 2024 compliance evaluation asks how management assesses AI risks, integrates them into enterprise risk management, governs AI use and prevents misuse [13]. An exit-ready seller should maintain an AI system inventory, business purpose, data sources, vendor and model dependency, human oversight, testing, incident history and contractual position. EU operations may also require an AI Act applicability assessment; Regulation (EU) 2024/1689 establishes a human-centric and risk-based framework with phased application [49]. Legal advice is required for scope and obligations.
Red-Flag Engine
Finding record
A red flag is an evidence-backed exception that may affect transaction value, timing, structure, disclosure or buyer confidence. The record should separate detection from conclusion. An automated test detects a signal. An analyst evaluates it. A professional or management owner determines response and disclosure.
| Field | Description |
|---|---|
| Finding ID | Stable reference used in room, report and issue tracker |
| Trigger | Rule, comparison or reviewer observation |
| Evidence | Source objects and exact pointers |
| Assertion | Narrow statement supported by the evidence |
| Impact domains | Price, cash, tax, legal, operational, timing or reputation |
| Materiality | Declared quantitative or qualitative basis |
| Counter-evidence | Contradictory or mitigating records |
| Owner and adviser | People responsible for response and advice |
| Status | Open, investigating, remediating, accepted, disclosed or closed |
| Closure evidence | Record that supports the final state |
Detection families
Deterministic rules are appropriate for exact tests: missing sequence numbers, duplicate payments, balance differences, late filings, unsigned contracts, expired licences, negative working-capital movements or ownership percentages that do not total correctly. Statistical methods may prioritise unusual journals, margins, customers, transactions or access patterns. Language models may identify semantic inconsistency across narratives and documents. Every method needs a recorded false-positive and false-negative evaluation.
Red-flag examples
[Unverified illustrative scenario] A family-owned distributor presents one individual as the shareholder. The commercial register, shareholder agreement and board correspondence indicate a nominee arrangement and appointment rights held by another family member. The agent creates a signal linking the records. Counsel determines the ownership and disclosure analysis.
[Unverified illustrative scenario] Management accounts show AED 6 million of adjusted EBITDA. The trial-balance bridge contains AED 1.2 million of proposed normalisations, including an owner salary, one-off advisory cost and an unsigned annual customer rebate. The system preserves the three proposals separately. The VDD adviser evaluates recurrence and evidence; the report never converts all three into accepted EBITDA automatically.
[Unverified illustrative scenario] The customer master shows 420 customers, while the invoiced-revenue population contains 447 legal entities. Entity resolution identifies group names and spelling variants, leaving 11 unmatched billed entities. The reconciliation remains open until finance confirms the population and treatment.
Triage
Severity should combine evidence quality, plausible impact, urgency and reversibility. A severe label should never be generated solely from model confidence. High-confidence extraction of a minor issue can be commercially unimportant. Low-confidence identification of a possible ownership or sanctions issue can require immediate human review.
Vdd Report Drafting Pipeline
Claim-first drafting
The report generator should work from an approved claim register. Each claim contains a statement, scope, period, units, evidence citations, calculation identifier, status, reviewer and limitations. The drafting agent converts accepted claims into narrative and tables. It cannot create an uncited consequential statement.
Source roles
The report should distinguish four source roles:
- Recorded fact: directly supported by a controlled source.
- Calculated result: produced by approved deterministic logic from controlled inputs.
- Management explanation: attributed to management and supported or uncorroborated as stated.
- Adviser finding: professional analysis within an engagement and review process.
This separation prevents a management explanation from being restated as an independently established fact. It also allows the reader to reproduce a calculated table and identify the data cut used.
Draft controls
The model context should contain only the approved evidence and claim set for the current section. The drafting prompt should prohibit unstated inference, require inline evidence identifiers and surface contradictions. A deterministic post-processor should check every number against the calculation registry, every defined period against the perimeter and every citation against a released source.
Review cycle
| Review | Core question | Evidence of completion |
|---|---|---|
| Preparer's check | Does the draft match the working papers? | Section checklist and changes |
| Finance review | Are amounts, policies and bridges correct? | Signed finance review record |
| Workstream review | Are domain findings accurate and complete? | Named reviewer acceptance |
| Legal review | Are disclosure, privilege and wording controlled? | Counsel-controlled status |
| Management factual accuracy | Are representations accurate and authorised? | Management response log |
| Final partner/director review | Is the report ready under engagement terms? | Final approval and document hash |
PCAOB AS 1215 requires documentation sufficient to understand the procedures, evidence and conclusions in an audit context [22]. T37 applies that documentation logic as a design principle. It does not characterise the VDD report as an audit.
Reliance and version control
The issued report receives a version, date, scope, addressee, reliance position and hash. Changes after issue require a controlled supplement or reissue. A live dashboard may help track updates, while a reader must still know which evidence and report version governed a decision.
Human Review And Sign-Off
Four-eye control
Every material finding should have a preparer and independent reviewer. Independence is role-based and conflict-aware. A system administrator who maintains the workflow may confirm execution but cannot substitute for the finance, legal or tax reviewer. The acceptance record names each role and retains time-stamped evidence.
Reserved actions
Reserved actions include defining deal perimeter; determining legal and beneficial ownership; approving accounting adjustments; expressing tax, legal or valuation conclusions; deciding privilege; accepting a management representation; approving disclosure; issuing the VDD report; and answering a buyer on a material matter. Tool permissions should make these actions technically unavailable to the agent.
Escalation
Escalation rules should be explicit. Examples include an ownership contradiction, possible sanctions match, evidence of misconduct, missing bank account, material tax filing gap, suspected data breach, forecast dependency on an unsigned contract or instruction to omit a relevant record. The workflow stops the affected output and routes the evidence to the appropriate owner. It should retain the trigger and response without exposing restricted content to unauthorised users.
Management representations
Management representation records should state the exact question, responding person, authority, date, answer, caveat and supporting evidence. A chat response copied into a report lacks adequate context. The system can organise and compare representations over time. It should flag changed answers and preserve both versions.
Security, Mcp And Permission Design
Identity
Every human, agent, service and tool receives a distinct identity. Shared accounts defeat attribution. Short-lived, audience-bound tokens and purpose-specific scopes align with MCP authorisation guidance [41]. The runtime should reject token passthrough and prevent an MCP server from using a client token with a downstream service for which it was not issued.
Permission matrix
| Capability | Agent | Preparer | Reviewer | Release owner |
|---|---|---|---|---|
| Read approved evidence | Scoped | Scoped | Scoped | Scoped |
| Create derived object | Yes | Yes | Yes | Yes |
| Change source record | No | No through VDD system | No | No |
| Propose finding | Yes | Yes | Yes | Yes |
| Accept finding | No | Yes within role | Yes within role | Yes within role |
| Publish document | No | No | No | Yes with manifest |
| Send buyer response | No | No unless authorised | No unless authorised | Separate transaction control |
Prompt injection and poisoned evidence
A document can contain instructions intended to manipulate a model. NCSC guidance identifies prompt-injection and data-poisoning threats [32,33]. The ingestion layer should treat document text as untrusted data, separate system instructions from content, disable arbitrary tool calls during extraction, restrict outbound connections and require schema-valid outputs. A document that says “ignore prior instructions” remains evidence text.
Data loss and exfiltration
The system should prevent unrestricted copy, download, web access and model retention. Logging should capture actor, tool, evidence identifiers, purpose, output identifier and policy decision. Logs need their own confidentiality, integrity and retention controls. A tool result should return the minimum fields necessary for the task.
Vendor and model risk
Anthropic's research on trustworthy agents, autonomy measurement and simulated agentic misalignment supports explicit oversight, testing and caution in sensitive environments [38-40]. The misalignment work reports simulated experiments and states that the authors were not aware of this behaviour in real-world deployments [40]. T37 therefore uses the research as a risk-design input and makes no claim that a particular deployed agent acted maliciously.
Agent Evaluation And Acceptance
Evaluation units
Agent evaluation should use transaction-representative tasks rather than general language benchmarks. Units include document classification, clause extraction, population reconciliation, finding detection, citation accuracy, contradiction handling, tool selection, abstention and escalation. Anthropic's guidance on agent evaluations emphasises tasks, graders and empirical analysis [37]. NIST AI RMF and the Generative AI Profile organise governance, mapping, measurement and management of risk [29-31].
Ground truth
A qualified reviewer creates or approves the reference answer. Difficult or ambiguous cases should retain an adjudication record. Ground truth can include acceptable answer variants and explicit abstention. The evaluation set should represent scanned documents, amendments, multilingual records, tables, missing pages, near duplicates, conflicting evidence and restricted files.
Metrics
| Metric | Unit | Acceptance question |
|---|---|---|
| Extraction precision and recall | Field or clause | Were material fields captured without invented values? |
| Reconciliation exactness | Row and total | Does deterministic output reproduce approved answers? |
| Citation validity | Claim | Does every citation support the stated claim? |
| Red-flag recall | Known issue | Did the workflow surface the issue for review? |
| False-positive burden | Finding | Can the review team absorb the noise? |
| Permission compliance | Attempted action | Did the system refuse prohibited access and action? |
| Abstention quality | Ambiguous task | Did it stop and escalate when evidence was insufficient? |
| Reproducibility | Repeated run | Can the same inputs and version recreate the output? |
Adversarial tests
The suite should include prompt injection in documents, misleading filenames, hidden text, corrupted files, unauthorised requests, stale registers, contradictory contracts, manipulated totals, partial exports and a tool that returns an error. The agent should preserve uncertainty and stop affected conclusions. A successful demonstration on clean documents does not satisfy the gate.
Acceptance threshold
Thresholds depend on task impact. Exact financial totals should require deterministic agreement. A legal-clause extraction tool may require very high recall and mandatory review. A low-risk folder suggestion can tolerate more error. The release record should state dataset, version, model, prompts, tools, thresholds, results, known limitations and approver.
Twelve-Month Readiness Roadmap
Evidence-gated schedule
The requested hook refers to a twelve-month roadmap compressed by agentic workflows. No observed programme data was supplied to establish a compression ratio. T37 therefore expresses twelve months as a reference sequence of gates. Teams may run independent workstreams in parallel after dependencies and capacity are known. Actual elapsed days, reviewer hours, rework, exceptions and transaction outcomes should be recorded.
| Reference period | Readiness objective | Exit evidence |
|---|---|---|
| Months 1-2 | Define perimeter, owners, governance and security | Approved charter, entity map and permission matrix |
| Months 2-3 | Acquire finance, tax, corporate and contract populations | Source manifests and completeness exceptions |
| Months 3-5 | Reconcile historical financials and cash | Accepted bridges and exception ledger |
| Months 4-6 | Review ownership, nominees, related parties and restructuring | Counsel and tax issue records |
| Months 5-7 | Build commercial, customer, supplier and operational analyses | Reproducible populations and metrics |
| Months 6-8 | Review HR, IP, privacy, cyber and regulatory workstreams | Accepted workstream checklists |
| Months 7-9 | Resolve material gaps and prepare management responses | Closure evidence and residual-risk decisions |
| Months 8-10 | Draft VDD report from approved claims | Section reviews and cited draft |
| Months 10-11 | Populate buyer room and run mock diligence | Released manifest and response log |
| Months 11-12 | Refresh cut-off, issue report and launch process | Final report, room and open-item register |
Parallelisation
Parallel work is safe when workstreams have independent sources and clear interfaces. Contract extraction can proceed while trial-balance mapping is reviewed. Ownership analysis may block related-party and sanctions conclusions. Historical financial reconciliation should precede quality-of-earnings conclusions. Privacy classification should precede broad model or adviser access.
Machine-speed target
“Machine speed” should mean rapid execution of a controlled, repeatable task after approved evidence is available. Examples include hashing 10,000 files, testing a ledger population, comparing defined fields or regenerating a cited draft. It should not imply instantaneous professional judgement, source remediation, management response or buyer agreement.
Capacity ledger
The programme records machine execution time, reviewer time, source-owner time, exception backlog and rework. An automation that reduces extraction time and increases review noise can raise total effort. The valid unit is accepted evidence or accepted finding per end-to-end hour, with quality and risk gates satisfied.
Illustrative Operating Case
Scenario
[Unverified illustrative scenario] A UAE-headquartered family distribution and services group is considering a majority sale. It has three operating entities, two legacy holding vehicles, 235 employees, several related-party property arrangements and seven years of financial records split across two accounting systems. The scenario is fictional and demonstrates the framework. It is not a Matchpoint or client case.
Baseline backlog
The initial inventory contains 8,400 files. Exact hashes identify 1,120 byte-for-byte duplicates. Near-duplicate logic proposes 340 candidate groups. The system creates 460 low-confidence OCR or extraction exceptions. Finance identifies AED 2.4 million of trial-balance-to-management-account differences across periods. Counsel identifies an unresolved nominee declaration and a lease with a related party. These figures are illustrative and do not represent observed performance.
Controlled run
The ingestion service preserves originals and builds proposed index entries. Finance's deterministic code maps the trial balance, and the agent drafts explanations for each difference using the evidence register. Legal counsel reviews the ownership graph and creates the authorised description. Tax advisers review related-party records and returns. The VDD drafting agent receives accepted claims only.
Results boundary
The scenario can illustrate workload accounting without claiming benefit. Assume 1,000 automated task units, 180 review exceptions and 35 material findings. Those numbers support capacity planning only. A claim of time saved would require a comparable manual baseline, identical scope, quality adjustment, recorded labour and observed outcomes. A claim of value preserved would require a causal and approved transaction record.
Decision
The readiness gate remains closed while the nominee matter, financial differences and related-party lease lack approved conclusions. Automation has made the open items visible and reproducible. It has not resolved their legal, accounting or commercial meaning.
Economics, Capacity And Implementation
Measurement framework
An implementation business case should measure acquisition cost, platform and model cost, integration, security, evaluation, professional review, source remediation, ongoing operation and incident response. Benefits can be observed as lower end-to-end hours for an accepted output, shorter elapsed time between approved gates, lower rework, higher population coverage or fewer buyer questions caused by preventable evidence gaps. Each metric needs a baseline and an approval owner.
Evidence states
| State | Meaning | Permitted claim |
|---|---|---|
| Proposed | Designed workflow or target | Describe as proposed |
| Tested | Run on an approved evaluation set | Report test scope and result |
| Piloted | Used in a controlled live workstream | Report observed pilot measures and limits |
| Operational | Accepted governance and repeated use | Report approved operating measures |
| Attributed | Causal financial link approved | Report approved value with method |
T37 remains at proposed-framework state. No approved live client benchmark, labour baseline, transaction outcome or attributed financial result was supplied. Attributed Matchpoint or client revenue, cash cost reduction, loss reduction and alpha therefore remain USD 0.
Ninety-day implementation start
Days 1 to 15 define authority, perimeter, data classes, prohibited actions and evaluation tasks. Days 16 to 30 build the evidence registry and one read-only connector. Days 31 to 45 implement one deterministic reconciliation and an exception ledger. Days 46 to 60 add a bounded agent for classification and cited drafting. Days 61 to 75 perform adversarial evaluation and professional review. Days 76 to 90 run a controlled workstream and decide whether evidence supports expansion.
Minimum viable scope
The first production scope should be one entity, one historical period, one source system and one workstream with a qualified reviewer. A suitable example is trial-balance-to-management-accounts reconciliation or a corporate-document completeness check. The scope should exclude final report issue, buyer communication and autonomous disclosure.
Buy, build or partner
The operating choice depends on data sensitivity, connector availability, security architecture, review capacity, custom workflow, volume and transaction frequency. Vendor claims should be tested in the seller's environment. Contract review should cover data use, retention, sub-processors, model training, geography, security, incident response, availability, export, deletion and audit rights.
Limitations And Conclusion
Limitations
This paper is a design framework. It contains no observed T37 client programme, VDD benchmark, transaction result, verified time saving or causal economic outcome. The illustrative cases do not establish performance. Legal, tax, accounting, audit, valuation, sanctions, privacy and employment requirements depend on facts, jurisdiction, engagement and current law. Source systems may be incomplete or wrong. Model and vendor capabilities change. A buyer remains entitled to perform independent diligence.
Conclusion
Agentic workflows can support exit readiness when every consequential output remains tied to controlled evidence, deterministic calculation and named human authority. The core asset is the evidence graph: source, hash, perimeter, transformation, contradiction, reviewer and release state. The data room, reconciliation ledger, red-flag register and report then become views over the same governed record.
The framework places speed after admissibility. A file can be processed quickly and remain unusable. A report can be drafted quickly and remain unsupported. A twelve-month programme can be reorganised into parallel evidence gates, while elapsed-time improvement must be measured. The seller's strongest position is an accurate, reproducible account of what is known, what is calculated, what management represents and what remains unresolved.
The implementation recommendation is one bounded workflow: one entity, one period, one evidence registry, one deterministic reconciliation, one agentic assistant, one professional reviewer and one acceptance record. Expansion follows measured quality, permission compliance, reviewer capacity and approved value. Transaction authority remains with management and appointed professionals.
References
[1] United Arab Emirates Cabinet. Cabinet Decision No. 109 of 2023 Concerning the Regulation of Beneficial Owner Procedures. Ministry of Economy and Tourism. https://www.moet.gov.ae/documents/20121/294745/Cabinet%2BDecision%2B109-2023%2BEnglish%2BVersion%2BPDF.pdf/1590f581-52c1-ac5c-19de-be97a879a240?t=1706692042660
[2] UAE Ministry of Economy and Tourism. Cabinet Resolution on the Regulation of Real Beneficiary Procedures. https://www.moet.gov.ae/en/-/ministry-of-economy-reviews-cabinet-resolution-on-the-organization-of-real-beneficiary-procedures-and-its-role-in-supporting-the-competitiveness-of-the-business-environment
[3] Financial Action Task Force. Guidance on Beneficial Ownership of Legal Persons. March 2023. https://www.fatf-gafi.org/content/fatf-gafi/en/publications/Fatfrecommendations/Guidance-Beneficial-Ownership-Legal-Persons.html
[4] Financial Action Task Force. The FATF Recommendations. Updated October 2025. https://www.fatf-gafi.org/en/publications/Fatfrecommendations/Fatf-recommendations.html
[5] Financial Action Task Force. FATF Glossary. https://www.fatf-gafi.org/en/pages/fatf-glossary.html
[6] United Arab Emirates. Federal Decree-Law No. 37 of 2022 Concerning Family Companies. Ministry of Economy and Tourism. https://www.moet.gov.ae/documents/20121/0/family%2Bcompany%2Benglish%2Bversion%2Bexamined%2Band%2Bcorrecetd.pdf/5639a956-fe15-6de2-a04e-c8f8ecb6c2bf
[7] United Arab Emirates. Federal Decree-Law No. 32 of 2021 on Commercial Companies. Ministry of Economy and Tourism. https://www.moec.gov.ae/documents/20121/376326/Commercial%2BCompanies.pdf/12d14f53-1a3e-47b4-8e70-fac3f672c403?t=1645596097819
[8] United Arab Emirates. Federal Decree-Law No. 46 of 2021 on Electronic Transactions and Trust Services. https://u.ae/-/media/Documents-2024/Federal-Decree-by-Law-No-46-of-2021-on-Electronic-Transactions-and-Trust-Services.pdf
[9] United Arab Emirates Government. Data Protection Laws. https://u.ae/en/about-the-uae/digital-uae/data/data-protection-laws
[10] UAE Ministry of Finance. Corporate Tax. https://mof.gov.ae/en/public-finance/tax/corporate-tax/
[11] UAE Federal Tax Authority. Transfer Pricing Guide. October 2023. https://tax.gov.ae/Datafolder/Files/Pdf/2023/Transfer%20Pricing%20Guide%20-%20EN%20-%2023%2010%202023.pdf
[12] UAE Ministry of Finance. Corporate Tax Decisions on Intra-Group Transfers, Taxable Income and Restructuring Relief. https://mof.gov.ae/en/news/ministry-of-finance-issues-new-corporate-tax-decisions-on-intra-group-transfers-determination-of-taxable-income-and-restructuring-relief/
[13] United States Department of Justice, Criminal Division. Evaluation of Corporate Compliance Programs. Updated September 2024. https://www.justice.gov/criminal-fraud/page/file/937501/download
[14] United States Department of Justice and Securities and Exchange Commission. A Resource Guide to the U.S. Foreign Corrupt Practices Act. Second Edition, updated December 2024. https://www.justice.gov/d9/pages/attachments/2020/07/03/fcpa-guide-2020_final.pdf
[15] United States Department of the Treasury, Office of Foreign Assets Control. A Framework for OFAC Compliance Commitments. May 2019. https://ofac.treasury.gov/media/16331/download
[16] UK Office of Financial Sanctions Implementation. Financial Sanctions Enforcement and Monetary Penalties Guidance. Updated 2026. https://www.gov.uk/government/publications/financial-sanctions-enforcement-and-monetary-penalties-guidance/financial-sanctions-enforcement-and-monetary-penalties-guidance
[17] OECD. Governments' Assessments of Corporate Anti-Corruption Compliance. 2025. https://www.oecd.org/content/dam/oecd/en/publications/reports/2025/03/governments-assessments-of-corporate-anti-corruption-compliance_6100e758/e798903c-en.pdf
[18] OECD. Due Diligence Guidance for Responsible Business Conduct. 2018. https://www.oecd.org/content/dam/oecd/en/publications/reports/2018/02/oecd-due-diligence-guidance-for-responsible-business-conduct_c669bd57/15f5f4b3-en.pdf
[19] UK Information Commissioner's Office. Due Diligence in Mergers and Acquisitions. https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/data-sharing/data-sharing-a-code-of-practice/due-diligence/
[20] European Commission. Principles of the GDPR. https://commission.europa.eu/law/law-topic/data-protection/information-business-and-organisations/principles-gdpr_en
[21] Public Company Accounting Oversight Board. AS 1105: Audit Evidence. https://pcaobus.org/oversight/standards/auditing-standards/details/AS1105
[22] Public Company Accounting Oversight Board. AS 1215: Audit Documentation. https://pcaobus.org/oversight/standards/auditing-standards/details/AS1215
[23] Public Company Accounting Oversight Board. Evaluating the Reliability of External Information Provided by the Company in Electronic Form. 2025. https://pcaobus.org/standards/documents/staff-guidance-examples-of-evaluating-the-reliability-of-external-information-provided-by-the-company-in-electronic-form.pdf
[24] International Auditing and Assurance Standards Board. ISRS 4400, Agreed-Upon Procedures Engagements. https://www.iaasb.org/consultations-projects/agreed-upon-procedures-isrs-4400
[25] IFRS Foundation. IFRS 3 Business Combinations. https://www.ifrs.org/content/dam/ifrs/publications/pdf-standards/english/2022/issued/part-a/ifrs-3-business-combinations.pdf?bypass=on
[26] IFRS Foundation. IAS 2 Inventories. https://www.ifrs.org/issued-standards/list-of-standards/ias-2-inventories/
[27] IFRS Foundation. IFRS for SMEs Accounting Standard Update. December 2025. https://www.ifrs.org/news-and-events/news/2025/12/december-2025-ifrs-for-smes-accounting-standard-update/
[28] International Valuation Standards Council. International Valuation Standards: IVS 104 Data and Inputs, IVS 105 Valuation Models and IVS 106 Documentation and Reporting. Effective 31 January 2025. https://ivsc.org/standards/
[29] National Institute of Standards and Technology. AI Risk Management Framework. https://www.nist.gov/itl/ai-risk-management-framework
[30] National Institute of Standards and Technology. Artificial Intelligence Risk Management Framework: Generative Artificial Intelligence Profile, NIST AI 600-1. July 2024. https://nvlpubs.nist.gov/nistpubs/ai/NIST.AI.600-1.pdf
[31] National Institute of Standards and Technology. AI RMF Core. https://airc.nist.gov/airmf-resources/airmf/5-sec-core/
[32] UK National Cyber Security Centre. Guidelines for Secure AI System Development. https://www.ncsc.gov.uk/files/Guidelines-for-secure-AI-system-development.pdf
[33] UK National Cyber Security Centre. AI and Cyber Security: What You Need to Know. https://www.ncsc.gov.uk/guidance/ai-and-cyber-security-what-you-need-to-know
[34] Anthropic. How Claude Tool Use Works. https://platform.claude.com/docs/en/agents-and-tools/tool-use/how-tool-use-works
[35] Anthropic. Tool Use Reference. https://platform.claude.com/docs/en/agents-and-tools/tool-use/tool-reference
[36] Anthropic. Managed Agent Tools. https://platform.claude.com/docs/en/managed-agents/tools
[37] Anthropic. Demystifying Evals for AI Agents. https://www.anthropic.com/engineering/demystifying-evals-for-ai-agents
[38] Anthropic. Towards Building More Trustworthy Agents. https://www.anthropic.com/research/trustworthy-agents
[39] Anthropic. Measuring AI Agent Autonomy in Practice. https://www.anthropic.com/research/measuring-agent-autonomy
[40] Anthropic. Agentic Misalignment: How LLMs Could Be Insider Threats. 2025. https://www.anthropic.com/research/agentic-misalignment
[41] Model Context Protocol. Authorization Specification. 18 June 2025. https://modelcontextprotocol.io/specification/2025-06-18/basic/authorization
[42] Model Context Protocol. Security Best Practices. https://modelcontextprotocol.io/docs/tutorials/security/security_best_practices
[43] Model Context Protocol. Client Best Practices. https://modelcontextprotocol.io/docs/develop/clients/client-best-practices
[44] Model Context Protocol. Tool Annotations. March 2026. https://blog.modelcontextprotocol.io/posts/2026-03-16-tool-annotations/
[45] Model Context Protocol. Authorization Tutorial. https://modelcontextprotocol.io/docs/tutorials/security/authorization
[46] National Institute of Standards and Technology. Cybersecurity Framework 2.0. February 2024. https://www.nist.gov/cyberframework
[47] National Institute of Standards and Technology. SP 800-207: Zero Trust Architecture. August 2020. https://csrc.nist.gov/pubs/sp/800/207/final
[48] National Institute of Standards and Technology. SP 1800-35: Implementing a Zero Trust Architecture. June 2025. https://csrc.nist.gov/pubs/sp/1800/35/final
[49] European Union. Regulation (EU) 2024/1689 Laying Down Harmonised Rules on Artificial Intelligence. https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=OJ%3AL_202401689
[50] OECD. G20/OECD Principles of Corporate Governance 2023. https://www.oecd.org/en/publications/g20-oecd-principles-of-corporate-governance-2023_ed750b30-en.html
[51] International Valuation Standards Council. Building Trust in Private Market Valuations. 2025. https://ivsc.org/building-trust-in-private-market-valuations-the-role-of-international-valuation-standards/
[52] UAE Ministry of Economy and Tourism. Financial Crimes Legislations. Updated 25 July 2026. https://www.moet.gov.ae/en/financial-crimes-legislations
Appendix A. Canonical Evidence Object
| Field | Example | Validation |
|---|---|---|
| evidence_id | EV-FIN-000184 | Unique and immutable |
| source_uri | vault://finance/tb-2025.xlsx | Approved repository only |
| sha256 | 64-character digest | Recalculate on acquisition |
| entity | Operating Company LLC | Must exist in perimeter register |
| period | 2025-01-01 to 2025-12-31 | ISO dates and declared timezone where needed |
| classification | Confidential-finance | Maps to access policy |
| extraction | Sheet TB, row 184 | Must resolve to bounded original location |
| transformation | Account map v3.2 | Versioned deterministic procedure |
| reviewer_state | Accepted | Named reviewer and timestamp required |
| supersedes | EV-FIN-000132 | Preserve prior object and reason |
The object also stores source owner, acquisition identity, file type, language, OCR confidence, currency, units, privilege state, personal-data class, retention, legal hold, citations and links to contradictions. It should be exported with the report working papers so that an authorised reviewer can reproduce the evidence path.
Appendix B. Red-Flag Record
- Create a narrow assertion that can be supported or rejected.
- Link every source and preserve contradictory evidence.
- Identify the rule, model or person that triggered the signal.
- Record quantitative and qualitative materiality separately.
- Assign management and professional owners.
- State the required decision and stop condition.
- Record proposed remediation and target evidence.
- Require reviewer acceptance before closure.
- Preserve the disclosed wording and report version.
- Reopen automatically when a linked source changes or a refresh date expires.
Appendix C. Agent-Run Manifest
| Control | Required record |
|---|---|
| Task | Exact bounded objective and prohibited actions |
| Runtime | Model, version, region and configuration |
| Instructions | System and task prompt hashes |
| Tools | Names, versions, scopes and MCP server identities |
| Inputs | Evidence IDs, versions and hashes |
| Outputs | Derived-object identifiers and hashes |
| Calculations | Code version, parameters, rounding and result |
| Permissions | Policy decision for every tool request |
| Exceptions | Errors, refusals, low-confidence outputs and escalations |
| Review | Preparer, reviewer, decision and timestamp |
Appendix D. Vdd Report Acceptance Checklist
- Scope, perimeter, period and reporting framework are explicit.
- Every number resolves to an approved calculation or source.
- Management explanations are attributed and their corroboration state is clear.
- Open issues, contradictory evidence and limitations are visible.
- Ownership and nominee analysis has counsel review.
- Tax conclusions have tax-adviser review.
- Personal and privileged information follows approved disclosure controls.
- Every released document appears on the signed data-room manifest.
- The report hash, version, date, addressee and reliance position are recorded.
- The agent has no publication, representation or transaction authority.
- Attributed Matchpoint or client revenue, cash cost reduction, loss reduction and alpha remain USD 0 until approved observed evidence exists.
Appendix E. Readiness Acceptance Record
| Gate | Owner | Evidence | Exceptions | Decision |
|---|---|---|---|---|
| Transaction perimeter | Deal lead | Approved entity and business map | Open perimeter items | Accept or hold |
| Evidence acquisition | Workstream leads | Population and file manifests | Missing and restricted items | Accept or hold |
| Financial reconciliation | Finance and VDD | Signed bridges and exception ledger | Unexplained differences | Accept or hold |
| Ownership and tax | Legal and tax | Reviewed graphs, filings and positions | Open legal or tax matters | Accept or hold |
| Report | Engagement lead | Cited reviewed draft | Unapproved claims | Accept or hold |
| Data-room release | Counsel and release owner | Signed hash manifest | Permission or disclosure issue | Release or hold |
| Launch | Seller board or delegate | Final package and residual-risk register | Conditions outstanding | Launch or hold |
The record should state actual elapsed time, machine execution time, reviewer hours, rework, issue counts and quality results. Any future claim of timeline compression or financial benefit should cite this observed evidence and its approved baseline.
Source Register
The full paper records the scope, evidence setting and limitations applied to these sources.
- [1] United Arab Emirates Cabinet. *Cabinet Decision No. 109 of 2023 Concerning the Regulation of Beneficial Owner Procedures*. Ministry of Economy and Tourism. Open source
- [2] UAE Ministry of Economy and Tourism. *Cabinet Resolution on the Regulation of Real Beneficiary Procedures*. Open source
- [3] Financial Action Task Force. *Guidance on Beneficial Ownership of Legal Persons*. March 2023. Open source
- [4] Financial Action Task Force. *The FATF Recommendations*. Updated October 2025. Open source
- [5] Financial Action Task Force. *FATF Glossary*. Open source
- [6] United Arab Emirates. *Federal Decree-Law No. 37 of 2022 Concerning Family Companies*. Ministry of Economy and Tourism. Open source
- [7] United Arab Emirates. *Federal Decree-Law No. 32 of 2021 on Commercial Companies*. Ministry of Economy and Tourism. Open source
- [8] United Arab Emirates. *Federal Decree-Law No. 46 of 2021 on Electronic Transactions and Trust Services*. Open source
- [9] United Arab Emirates Government. *Data Protection Laws*. Open source
- [10] UAE Ministry of Finance. *Corporate Tax*. Open source
- [11] UAE Federal Tax Authority. *Transfer Pricing Guide*. October 2023. Open source
- [12] UAE Ministry of Finance. *Corporate Tax Decisions on Intra-Group Transfers, Taxable Income and Restructuring Relief*. Open source
- [13] United States Department of Justice, Criminal Division. *Evaluation of Corporate Compliance Programs*. Updated September 2024. Open source
- [14] United States Department of Justice and Securities and Exchange Commission. *A Resource Guide to the U.S. Foreign Corrupt Practices Act*. Second Edition, updated December 2024. Open source
- [15] United States Department of the Treasury, Office of Foreign Assets Control. *A Framework for OFAC Compliance Commitments*. May 2019. Open source
- [16] UK Office of Financial Sanctions Implementation. *Financial Sanctions Enforcement and Monetary Penalties Guidance*. Updated 2026. Open source
- [17] OECD. *Governments' Assessments of Corporate Anti-Corruption Compliance*. 2025. Open source
- [18] OECD. *Due Diligence Guidance for Responsible Business Conduct*. 2018. Open source
- [19] UK Information Commissioner's Office. *Due Diligence in Mergers and Acquisitions*. Open source
- [20] European Commission. *Principles of the GDPR*. Open source
- [21] Public Company Accounting Oversight Board. *AS 1105: Audit Evidence*. Open source
- [22] Public Company Accounting Oversight Board. *AS 1215: Audit Documentation*. Open source
- [23] Public Company Accounting Oversight Board. *Evaluating the Reliability of External Information Provided by the Company in Electronic Form*. 2025. Open source
- [24] International Auditing and Assurance Standards Board. *ISRS 4400, Agreed-Upon Procedures Engagements*. Open source
- [25] IFRS Foundation. *IFRS 3 Business Combinations*. Open source
- [26] IFRS Foundation. *IAS 2 Inventories*. Open source
- [27] IFRS Foundation. *IFRS for SMEs Accounting Standard Update*. December 2025. Open source
- [28] International Valuation Standards Council. *International Valuation Standards: IVS 104 Data and Inputs, IVS 105 Valuation Models and IVS 106 Documentation and Reporting*. Effective 31 January 2025. Open source
- [29] National Institute of Standards and Technology. *AI Risk Management Framework*. Open source
- [30] National Institute of Standards and Technology. *Artificial Intelligence Risk Management Framework: Generative Artificial Intelligence Profile, NIST AI 600-1*. July 2024. Open source
- [31] National Institute of Standards and Technology. *AI RMF Core*. Open source
- [32] UK National Cyber Security Centre. *Guidelines for Secure AI System Development*. Open source
- [33] UK National Cyber Security Centre. *AI and Cyber Security: What You Need to Know*. Open source
- [34] Anthropic. *How Claude Tool Use Works*. Open source
- [35] Anthropic. *Tool Use Reference*. Open source
- [36] Anthropic. *Managed Agent Tools*. Open source
- [37] Anthropic. *Demystifying Evals for AI Agents*. Open source
- [38] Anthropic. *Towards Building More Trustworthy Agents*. Open source
- [39] Anthropic. *Measuring AI Agent Autonomy in Practice*. Open source
- [40] Anthropic. *Agentic Misalignment: How LLMs Could Be Insider Threats*. 2025. Open source
- [41] Model Context Protocol. *Authorization Specification*. 18 June 2025. Open source
- [42] Model Context Protocol. *Security Best Practices*. Open source
- [43] Model Context Protocol. *Client Best Practices*. Open source
- [44] Model Context Protocol. *Tool Annotations*. March 2026. Open source
- [45] Model Context Protocol. *Authorization Tutorial*. Open source
- [46] National Institute of Standards and Technology. *Cybersecurity Framework 2.0*. February 2024. Open source
- [47] National Institute of Standards and Technology. *SP 800-207: Zero Trust Architecture*. August 2020. Open source
- [48] National Institute of Standards and Technology. *SP 1800-35: Implementing a Zero Trust Architecture*. June 2025. Open source
- [49] European Union. *Regulation (EU) 2024/1689 Laying Down Harmonised Rules on Artificial Intelligence*. Open source
- [50] OECD. *G20/OECD Principles of Corporate Governance 2023*. Open source
- [51] International Valuation Standards Council. *Building Trust in Private Market Valuations*. 2025. Open source
- [52] UAE Ministry of Economy and Tourism. *Financial Crimes Legislations*. Updated 25 July 2026. Open source
